Law / United States / Texas
Cybersecurity Program safe harbor from exemplary damages (S.B. 2610)
Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 September 2025.
A security baseline statutes rule binding private bodies.
As of 12 September 2026.
What it requires
- This chapter applies only to a business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information, as those terms are defined by Section 521.002.
- It is a safe harbor, not a duty: if such an entity is sued over a breach of system security and demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program meeting Section 542.004's requirements, the claimant may not recover exemplary damages from it. A qualifying program must contain administrative, technical, and physical safeguards; conform to a named industry-recognized cybersecurity framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000-series, the HITRUST Common Security Framework, the Secure Controls Framework, SOC 2, or a similar framework); and be scaled by headcount: simplified measures such as password policies and employee training below 20 employees, the CIS Controls Implementation Group 1 from 20 to 99 employees, and full conformance with a named framework from 100 to 249 employees.
- The chapter creates no duty to adopt a program and no cause of action of its own; it only removes exemplary-damages exposure for a qualifying entity that already has one at the time of a breach.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information may invoke a safe harbor from exemplary damages. In an action arising from a breach of system security, such an entity may not be held liable for exemplary damages if it demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program conforming to a named industry-recognized framework and scaled to its size. The chapter creates a safe harbor from a category of damages, not a freestanding duty to adopt a program.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official statute text, Texas Business and Commerce Code, Cybersecurity Program (S.B. 2610, 2025)